ruby-openid
A library for consuming and serving OpenID identities.
Activity
- Latest release
- 6y ago
- Total releases
- 29
- Cadence
- ~3 months
- Last 12 months
- 0
Details
- License
- unknown
- First release
- May 10, 2006
| Version | Released | |
|---|---|---|
2.9.2
patch
| ||
2.9.1
minor
| ||
2.8.0
minor
1 CVE
CVE-2019-11027
GHSA-fqfj-cmh6-hj49
Jun 13, 2019
ruby-openid SSRF via claimed_id request
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Ruby OpenID (aka ruby-openid) through 2.8.0 is vulnerable to SSRF. Ruby-openid performs discovery first, and then verification. This allows an attacker to change the URL used for discovery and trick the server into connecting to the URL, which might be a private server not publicly accessible. Severity can range from medium to critical, depending on how a web application developer chose to employ the ruby-openid library. Developers who based their OpenID integration heavily on the "example app" provided by the project are at highest risk. Affected versions
1.0
1.0.1
1.0.2
1.1.1
1.1.2
1.1.3
1.1.4
2.0.1
2.0.2
2.0.3
2.0.4
2.1.2
+ 15 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
Fixed in
2.9.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
2.7.0
minor
1 CVE
CVE-2019-11027
GHSA-fqfj-cmh6-hj49
Jun 13, 2019
ruby-openid SSRF via claimed_id request
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Ruby OpenID (aka ruby-openid) through 2.8.0 is vulnerable to SSRF. Ruby-openid performs discovery first, and then verification. This allows an attacker to change the URL used for discovery and trick the server into connecting to the URL, which might be a private server not publicly accessible. Severity can range from medium to critical, depending on how a web application developer chose to employ the ruby-openid library. Developers who based their OpenID integration heavily on the "example app" provided by the project are at highest risk. Affected versions
1.0
1.0.1
1.0.2
1.1.1
1.1.2
1.1.3
1.1.4
2.0.1
2.0.2
2.0.3
2.0.4
2.1.2
+ 15 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
Fixed in
2.9.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
2.6.0
minor
1 CVE
CVE-2019-11027
GHSA-fqfj-cmh6-hj49
Jun 13, 2019
ruby-openid SSRF via claimed_id request
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Ruby OpenID (aka ruby-openid) through 2.8.0 is vulnerable to SSRF. Ruby-openid performs discovery first, and then verification. This allows an attacker to change the URL used for discovery and trick the server into connecting to the URL, which might be a private server not publicly accessible. Severity can range from medium to critical, depending on how a web application developer chose to employ the ruby-openid library. Developers who based their OpenID integration heavily on the "example app" provided by the project are at highest risk. Affected versions
1.0
1.0.1
1.0.2
1.1.1
1.1.2
1.1.3
1.1.4
2.0.1
2.0.2
2.0.3
2.0.4
2.1.2
+ 15 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
Fixed in
2.9.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
2.5.0
minor
1 CVE
CVE-2019-11027
GHSA-fqfj-cmh6-hj49
Jun 13, 2019
ruby-openid SSRF via claimed_id request
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Ruby OpenID (aka ruby-openid) through 2.8.0 is vulnerable to SSRF. Ruby-openid performs discovery first, and then verification. This allows an attacker to change the URL used for discovery and trick the server into connecting to the URL, which might be a private server not publicly accessible. Severity can range from medium to critical, depending on how a web application developer chose to employ the ruby-openid library. Developers who based their OpenID integration heavily on the "example app" provided by the project are at highest risk. Affected versions
1.0
1.0.1
1.0.2
1.1.1
1.1.2
1.1.3
1.1.4
2.0.1
2.0.2
2.0.3
2.0.4
2.1.2
+ 15 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
Fixed in
2.9.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
2.4.0
minor
1 CVE
CVE-2019-11027
GHSA-fqfj-cmh6-hj49
Jun 13, 2019
ruby-openid SSRF via claimed_id request
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Ruby OpenID (aka ruby-openid) through 2.8.0 is vulnerable to SSRF. Ruby-openid performs discovery first, and then verification. This allows an attacker to change the URL used for discovery and trick the server into connecting to the URL, which might be a private server not publicly accessible. Severity can range from medium to critical, depending on how a web application developer chose to employ the ruby-openid library. Developers who based their OpenID integration heavily on the "example app" provided by the project are at highest risk. Affected versions
1.0
1.0.1
1.0.2
1.1.1
1.1.2
1.1.3
1.1.4
2.0.1
2.0.2
2.0.3
2.0.4
2.1.2
+ 15 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
Fixed in
2.9.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
2.3.0
minor
1 CVE
CVE-2019-11027
GHSA-fqfj-cmh6-hj49
Jun 13, 2019
ruby-openid SSRF via claimed_id request
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Ruby OpenID (aka ruby-openid) through 2.8.0 is vulnerable to SSRF. Ruby-openid performs discovery first, and then verification. This allows an attacker to change the URL used for discovery and trick the server into connecting to the URL, which might be a private server not publicly accessible. Severity can range from medium to critical, depending on how a web application developer chose to employ the ruby-openid library. Developers who based their OpenID integration heavily on the "example app" provided by the project are at highest risk. Affected versions
1.0
1.0.1
1.0.2
1.1.1
1.1.2
1.1.3
1.1.4
2.0.1
2.0.2
2.0.3
2.0.4
2.1.2
+ 15 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
Fixed in
2.9.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
2.2.3
patch
1 CVE
CVE-2019-11027
GHSA-fqfj-cmh6-hj49
Jun 13, 2019
ruby-openid SSRF via claimed_id request
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Ruby OpenID (aka ruby-openid) through 2.8.0 is vulnerable to SSRF. Ruby-openid performs discovery first, and then verification. This allows an attacker to change the URL used for discovery and trick the server into connecting to the URL, which might be a private server not publicly accessible. Severity can range from medium to critical, depending on how a web application developer chose to employ the ruby-openid library. Developers who based their OpenID integration heavily on the "example app" provided by the project are at highest risk. Affected versions
1.0
1.0.1
1.0.2
1.1.1
1.1.2
1.1.3
1.1.4
2.0.1
2.0.2
2.0.3
2.0.4
2.1.2
+ 15 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
Fixed in
2.9.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
2.2.2
patch
1 CVE
CVE-2019-11027
GHSA-fqfj-cmh6-hj49
Jun 13, 2019
ruby-openid SSRF via claimed_id request
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Ruby OpenID (aka ruby-openid) through 2.8.0 is vulnerable to SSRF. Ruby-openid performs discovery first, and then verification. This allows an attacker to change the URL used for discovery and trick the server into connecting to the URL, which might be a private server not publicly accessible. Severity can range from medium to critical, depending on how a web application developer chose to employ the ruby-openid library. Developers who based their OpenID integration heavily on the "example app" provided by the project are at highest risk. Affected versions
1.0
1.0.1
1.0.2
1.1.1
1.1.2
1.1.3
1.1.4
2.0.1
2.0.2
2.0.3
2.0.4
2.1.2
+ 15 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
Fixed in
2.9.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
2.2.1
patch
2 CVEs
CVE-2019-11027
GHSA-fqfj-cmh6-hj49
Jun 13, 2019
ruby-openid SSRF via claimed_id request
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Ruby OpenID (aka ruby-openid) through 2.8.0 is vulnerable to SSRF. Ruby-openid performs discovery first, and then verification. This allows an attacker to change the URL used for discovery and trick the server into connecting to the URL, which might be a private server not publicly accessible. Severity can range from medium to critical, depending on how a web application developer chose to employ the ruby-openid library. Developers who based their OpenID integration heavily on the "example app" provided by the project are at highest risk. Affected versions
1.0
1.0.1
1.0.2
1.1.1
1.1.2
1.1.3
1.1.4
2.0.1
2.0.2
2.0.3
2.0.4
2.1.2
+ 15 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
Fixed in
2.9.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2013-1812
GHSA-6c8p-qphv-668v
Oct 24, 2017
Denial of service in ruby-openid
Medium
The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of service (CPU consumption) via (1) a large XRDS document or (2) an XML Entity Expansion (XEE) attack. Affected versions
1.0
1.0.1
1.0.2
1.1.1
1.1.2
1.1.3
1.1.4
2.0.1
2.0.2
2.0.3
2.0.4
2.1.2
+ 7 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
Fixed in
2.2.2
References
Updated Dec 05, 2024 · Source: OSV.dev | ||
2.2.0
minor
2 CVEs
CVE-2019-11027
GHSA-fqfj-cmh6-hj49
Jun 13, 2019
ruby-openid SSRF via claimed_id request
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Ruby OpenID (aka ruby-openid) through 2.8.0 is vulnerable to SSRF. Ruby-openid performs discovery first, and then verification. This allows an attacker to change the URL used for discovery and trick the server into connecting to the URL, which might be a private server not publicly accessible. Severity can range from medium to critical, depending on how a web application developer chose to employ the ruby-openid library. Developers who based their OpenID integration heavily on the "example app" provided by the project are at highest risk. Affected versions
1.0
1.0.1
1.0.2
1.1.1
1.1.2
1.1.3
1.1.4
2.0.1
2.0.2
2.0.3
2.0.4
2.1.2
+ 15 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
Fixed in
2.9.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2013-1812
GHSA-6c8p-qphv-668v
Oct 24, 2017
Denial of service in ruby-openid
Medium
The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of service (CPU consumption) via (1) a large XRDS document or (2) an XML Entity Expansion (XEE) attack. Affected versions
1.0
1.0.1
1.0.2
1.1.1
1.1.2
1.1.3
1.1.4
2.0.1
2.0.2
2.0.3
2.0.4
2.1.2
+ 7 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
Fixed in
2.2.2
References
Updated Dec 05, 2024 · Source: OSV.dev | ||
2.1.8
patch
2 CVEs
CVE-2019-11027
GHSA-fqfj-cmh6-hj49
Jun 13, 2019
ruby-openid SSRF via claimed_id request
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Ruby OpenID (aka ruby-openid) through 2.8.0 is vulnerable to SSRF. Ruby-openid performs discovery first, and then verification. This allows an attacker to change the URL used for discovery and trick the server into connecting to the URL, which might be a private server not publicly accessible. Severity can range from medium to critical, depending on how a web application developer chose to employ the ruby-openid library. Developers who based their OpenID integration heavily on the "example app" provided by the project are at highest risk. Affected versions
1.0
1.0.1
1.0.2
1.1.1
1.1.2
1.1.3
1.1.4
2.0.1
2.0.2
2.0.3
2.0.4
2.1.2
+ 15 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
Fixed in
2.9.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2013-1812
GHSA-6c8p-qphv-668v
Oct 24, 2017
Denial of service in ruby-openid
Medium
The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of service (CPU consumption) via (1) a large XRDS document or (2) an XML Entity Expansion (XEE) attack. Affected versions
1.0
1.0.1
1.0.2
1.1.1
1.1.2
1.1.3
1.1.4
2.0.1
2.0.2
2.0.3
2.0.4
2.1.2
+ 7 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
Fixed in
2.2.2
References
Updated Dec 05, 2024 · Source: OSV.dev | ||
2.1.7
patch
2 CVEs
CVE-2019-11027
GHSA-fqfj-cmh6-hj49
Jun 13, 2019
ruby-openid SSRF via claimed_id request
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Ruby OpenID (aka ruby-openid) through 2.8.0 is vulnerable to SSRF. Ruby-openid performs discovery first, and then verification. This allows an attacker to change the URL used for discovery and trick the server into connecting to the URL, which might be a private server not publicly accessible. Severity can range from medium to critical, depending on how a web application developer chose to employ the ruby-openid library. Developers who based their OpenID integration heavily on the "example app" provided by the project are at highest risk. Affected versions
1.0
1.0.1
1.0.2
1.1.1
1.1.2
1.1.3
1.1.4
2.0.1
2.0.2
2.0.3
2.0.4
2.1.2
+ 15 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
Fixed in
2.9.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2013-1812
GHSA-6c8p-qphv-668v
Oct 24, 2017
Denial of service in ruby-openid
Medium
The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of service (CPU consumption) via (1) a large XRDS document or (2) an XML Entity Expansion (XEE) attack. Affected versions
1.0
1.0.1
1.0.2
1.1.1
1.1.2
1.1.3
1.1.4
2.0.1
2.0.2
2.0.3
2.0.4
2.1.2
+ 7 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
Fixed in
2.2.2
References
Updated Dec 05, 2024 · Source: OSV.dev | ||
2.1.6
patch
2 CVEs
CVE-2019-11027
GHSA-fqfj-cmh6-hj49
Jun 13, 2019
ruby-openid SSRF via claimed_id request
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Ruby OpenID (aka ruby-openid) through 2.8.0 is vulnerable to SSRF. Ruby-openid performs discovery first, and then verification. This allows an attacker to change the URL used for discovery and trick the server into connecting to the URL, which might be a private server not publicly accessible. Severity can range from medium to critical, depending on how a web application developer chose to employ the ruby-openid library. Developers who based their OpenID integration heavily on the "example app" provided by the project are at highest risk. Affected versions
1.0
1.0.1
1.0.2
1.1.1
1.1.2
1.1.3
1.1.4
2.0.1
2.0.2
2.0.3
2.0.4
2.1.2
+ 15 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
Fixed in
2.9.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2013-1812
GHSA-6c8p-qphv-668v
Oct 24, 2017
Denial of service in ruby-openid
Medium
The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of service (CPU consumption) via (1) a large XRDS document or (2) an XML Entity Expansion (XEE) attack. Affected versions
1.0
1.0.1
1.0.2
1.1.1
1.1.2
1.1.3
1.1.4
2.0.1
2.0.2
2.0.3
2.0.4
2.1.2
+ 7 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
Fixed in
2.2.2
References
Updated Dec 05, 2024 · Source: OSV.dev | ||
2.1.5
patch
2 CVEs
CVE-2019-11027
GHSA-fqfj-cmh6-hj49
Jun 13, 2019
ruby-openid SSRF via claimed_id request
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Ruby OpenID (aka ruby-openid) through 2.8.0 is vulnerable to SSRF. Ruby-openid performs discovery first, and then verification. This allows an attacker to change the URL used for discovery and trick the server into connecting to the URL, which might be a private server not publicly accessible. Severity can range from medium to critical, depending on how a web application developer chose to employ the ruby-openid library. Developers who based their OpenID integration heavily on the "example app" provided by the project are at highest risk. Affected versions
1.0
1.0.1
1.0.2
1.1.1
1.1.2
1.1.3
1.1.4
2.0.1
2.0.2
2.0.3
2.0.4
2.1.2
+ 15 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
Fixed in
2.9.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2013-1812
GHSA-6c8p-qphv-668v
Oct 24, 2017
Denial of service in ruby-openid
Medium
The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of service (CPU consumption) via (1) a large XRDS document or (2) an XML Entity Expansion (XEE) attack. Affected versions
1.0
1.0.1
1.0.2
1.1.1
1.1.2
1.1.3
1.1.4
2.0.1
2.0.2
2.0.3
2.0.4
2.1.2
+ 7 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
Fixed in
2.2.2
References
Updated Dec 05, 2024 · Source: OSV.dev | ||
2.1.4
patch
2 CVEs
CVE-2019-11027
GHSA-fqfj-cmh6-hj49
Jun 13, 2019
ruby-openid SSRF via claimed_id request
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Ruby OpenID (aka ruby-openid) through 2.8.0 is vulnerable to SSRF. Ruby-openid performs discovery first, and then verification. This allows an attacker to change the URL used for discovery and trick the server into connecting to the URL, which might be a private server not publicly accessible. Severity can range from medium to critical, depending on how a web application developer chose to employ the ruby-openid library. Developers who based their OpenID integration heavily on the "example app" provided by the project are at highest risk. Affected versions
1.0
1.0.1
1.0.2
1.1.1
1.1.2
1.1.3
1.1.4
2.0.1
2.0.2
2.0.3
2.0.4
2.1.2
+ 15 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
Fixed in
2.9.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2013-1812
GHSA-6c8p-qphv-668v
Oct 24, 2017
Denial of service in ruby-openid
Medium
The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of service (CPU consumption) via (1) a large XRDS document or (2) an XML Entity Expansion (XEE) attack. Affected versions
1.0
1.0.1
1.0.2
1.1.1
1.1.2
1.1.3
1.1.4
2.0.1
2.0.2
2.0.3
2.0.4
2.1.2
+ 7 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
Fixed in
2.2.2
References
Updated Dec 05, 2024 · Source: OSV.dev | ||
2.1.2
minor
2 CVEs
CVE-2019-11027
GHSA-fqfj-cmh6-hj49
Jun 13, 2019
ruby-openid SSRF via claimed_id request
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Ruby OpenID (aka ruby-openid) through 2.8.0 is vulnerable to SSRF. Ruby-openid performs discovery first, and then verification. This allows an attacker to change the URL used for discovery and trick the server into connecting to the URL, which might be a private server not publicly accessible. Severity can range from medium to critical, depending on how a web application developer chose to employ the ruby-openid library. Developers who based their OpenID integration heavily on the "example app" provided by the project are at highest risk. Affected versions
1.0
1.0.1
1.0.2
1.1.1
1.1.2
1.1.3
1.1.4
2.0.1
2.0.2
2.0.3
2.0.4
2.1.2
+ 15 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
Fixed in
2.9.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2013-1812
GHSA-6c8p-qphv-668v
Oct 24, 2017
Denial of service in ruby-openid
Medium
The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of service (CPU consumption) via (1) a large XRDS document or (2) an XML Entity Expansion (XEE) attack. Affected versions
1.0
1.0.1
1.0.2
1.1.1
1.1.2
1.1.3
1.1.4
2.0.1
2.0.2
2.0.3
2.0.4
2.1.2
+ 7 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
Fixed in
2.2.2
References
Updated Dec 05, 2024 · Source: OSV.dev | ||
2.0.4
patch
2 CVEs
CVE-2019-11027
GHSA-fqfj-cmh6-hj49
Jun 13, 2019
ruby-openid SSRF via claimed_id request
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Ruby OpenID (aka ruby-openid) through 2.8.0 is vulnerable to SSRF. Ruby-openid performs discovery first, and then verification. This allows an attacker to change the URL used for discovery and trick the server into connecting to the URL, which might be a private server not publicly accessible. Severity can range from medium to critical, depending on how a web application developer chose to employ the ruby-openid library. Developers who based their OpenID integration heavily on the "example app" provided by the project are at highest risk. Affected versions
1.0
1.0.1
1.0.2
1.1.1
1.1.2
1.1.3
1.1.4
2.0.1
2.0.2
2.0.3
2.0.4
2.1.2
+ 15 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
Fixed in
2.9.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2013-1812
GHSA-6c8p-qphv-668v
Oct 24, 2017
Denial of service in ruby-openid
Medium
The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of service (CPU consumption) via (1) a large XRDS document or (2) an XML Entity Expansion (XEE) attack. Affected versions
1.0
1.0.1
1.0.2
1.1.1
1.1.2
1.1.3
1.1.4
2.0.1
2.0.2
2.0.3
2.0.4
2.1.2
+ 7 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
Fixed in
2.2.2
References
Updated Dec 05, 2024 · Source: OSV.dev | ||
2.0.3
patch
2 CVEs
CVE-2019-11027
GHSA-fqfj-cmh6-hj49
Jun 13, 2019
ruby-openid SSRF via claimed_id request
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Ruby OpenID (aka ruby-openid) through 2.8.0 is vulnerable to SSRF. Ruby-openid performs discovery first, and then verification. This allows an attacker to change the URL used for discovery and trick the server into connecting to the URL, which might be a private server not publicly accessible. Severity can range from medium to critical, depending on how a web application developer chose to employ the ruby-openid library. Developers who based their OpenID integration heavily on the "example app" provided by the project are at highest risk. Affected versions
1.0
1.0.1
1.0.2
1.1.1
1.1.2
1.1.3
1.1.4
2.0.1
2.0.2
2.0.3
2.0.4
2.1.2
+ 15 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
Fixed in
2.9.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2013-1812
GHSA-6c8p-qphv-668v
Oct 24, 2017
Denial of service in ruby-openid
Medium
The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of service (CPU consumption) via (1) a large XRDS document or (2) an XML Entity Expansion (XEE) attack. Affected versions
1.0
1.0.1
1.0.2
1.1.1
1.1.2
1.1.3
1.1.4
2.0.1
2.0.2
2.0.3
2.0.4
2.1.2
+ 7 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
Fixed in
2.2.2
References
Updated Dec 05, 2024 · Source: OSV.dev | ||
2.0.2
patch
2 CVEs
CVE-2019-11027
GHSA-fqfj-cmh6-hj49
Jun 13, 2019
ruby-openid SSRF via claimed_id request
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Ruby OpenID (aka ruby-openid) through 2.8.0 is vulnerable to SSRF. Ruby-openid performs discovery first, and then verification. This allows an attacker to change the URL used for discovery and trick the server into connecting to the URL, which might be a private server not publicly accessible. Severity can range from medium to critical, depending on how a web application developer chose to employ the ruby-openid library. Developers who based their OpenID integration heavily on the "example app" provided by the project are at highest risk. Affected versions
1.0
1.0.1
1.0.2
1.1.1
1.1.2
1.1.3
1.1.4
2.0.1
2.0.2
2.0.3
2.0.4
2.1.2
+ 15 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
Fixed in
2.9.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2013-1812
GHSA-6c8p-qphv-668v
Oct 24, 2017
Denial of service in ruby-openid
Medium
The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of service (CPU consumption) via (1) a large XRDS document or (2) an XML Entity Expansion (XEE) attack. Affected versions
1.0
1.0.1
1.0.2
1.1.1
1.1.2
1.1.3
1.1.4
2.0.1
2.0.2
2.0.3
2.0.4
2.1.2
+ 7 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
Fixed in
2.2.2
References
Updated Dec 05, 2024 · Source: OSV.dev | ||
2.0.1
major
2 CVEs
CVE-2019-11027
GHSA-fqfj-cmh6-hj49
Jun 13, 2019
ruby-openid SSRF via claimed_id request
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Ruby OpenID (aka ruby-openid) through 2.8.0 is vulnerable to SSRF. Ruby-openid performs discovery first, and then verification. This allows an attacker to change the URL used for discovery and trick the server into connecting to the URL, which might be a private server not publicly accessible. Severity can range from medium to critical, depending on how a web application developer chose to employ the ruby-openid library. Developers who based their OpenID integration heavily on the "example app" provided by the project are at highest risk. Affected versions
1.0
1.0.1
1.0.2
1.1.1
1.1.2
1.1.3
1.1.4
2.0.1
2.0.2
2.0.3
2.0.4
2.1.2
+ 15 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
Fixed in
2.9.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2013-1812
GHSA-6c8p-qphv-668v
Oct 24, 2017
Denial of service in ruby-openid
Medium
The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of service (CPU consumption) via (1) a large XRDS document or (2) an XML Entity Expansion (XEE) attack. Affected versions
1.0
1.0.1
1.0.2
1.1.1
1.1.2
1.1.3
1.1.4
2.0.1
2.0.2
2.0.3
2.0.4
2.1.2
+ 7 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
Fixed in
2.2.2
References
Updated Dec 05, 2024 · Source: OSV.dev | ||
1.1.4
patch
2 CVEs
CVE-2019-11027
GHSA-fqfj-cmh6-hj49
Jun 13, 2019
ruby-openid SSRF via claimed_id request
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Ruby OpenID (aka ruby-openid) through 2.8.0 is vulnerable to SSRF. Ruby-openid performs discovery first, and then verification. This allows an attacker to change the URL used for discovery and trick the server into connecting to the URL, which might be a private server not publicly accessible. Severity can range from medium to critical, depending on how a web application developer chose to employ the ruby-openid library. Developers who based their OpenID integration heavily on the "example app" provided by the project are at highest risk. Affected versions
1.0
1.0.1
1.0.2
1.1.1
1.1.2
1.1.3
1.1.4
2.0.1
2.0.2
2.0.3
2.0.4
2.1.2
+ 15 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
Fixed in
2.9.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2013-1812
GHSA-6c8p-qphv-668v
Oct 24, 2017
Denial of service in ruby-openid
Medium
The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of service (CPU consumption) via (1) a large XRDS document or (2) an XML Entity Expansion (XEE) attack. Affected versions
1.0
1.0.1
1.0.2
1.1.1
1.1.2
1.1.3
1.1.4
2.0.1
2.0.2
2.0.3
2.0.4
2.1.2
+ 7 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
Fixed in
2.2.2
References
Updated Dec 05, 2024 · Source: OSV.dev | ||
1.1.3
patch
2 CVEs
CVE-2019-11027
GHSA-fqfj-cmh6-hj49
Jun 13, 2019
ruby-openid SSRF via claimed_id request
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Ruby OpenID (aka ruby-openid) through 2.8.0 is vulnerable to SSRF. Ruby-openid performs discovery first, and then verification. This allows an attacker to change the URL used for discovery and trick the server into connecting to the URL, which might be a private server not publicly accessible. Severity can range from medium to critical, depending on how a web application developer chose to employ the ruby-openid library. Developers who based their OpenID integration heavily on the "example app" provided by the project are at highest risk. Affected versions
1.0
1.0.1
1.0.2
1.1.1
1.1.2
1.1.3
1.1.4
2.0.1
2.0.2
2.0.3
2.0.4
2.1.2
+ 15 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
Fixed in
2.9.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2013-1812
GHSA-6c8p-qphv-668v
Oct 24, 2017
Denial of service in ruby-openid
Medium
The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of service (CPU consumption) via (1) a large XRDS document or (2) an XML Entity Expansion (XEE) attack. Affected versions
1.0
1.0.1
1.0.2
1.1.1
1.1.2
1.1.3
1.1.4
2.0.1
2.0.2
2.0.3
2.0.4
2.1.2
+ 7 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
Fixed in
2.2.2
References
Updated Dec 05, 2024 · Source: OSV.dev | ||
1.1.2
patch
2 CVEs
CVE-2019-11027
GHSA-fqfj-cmh6-hj49
Jun 13, 2019
ruby-openid SSRF via claimed_id request
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Ruby OpenID (aka ruby-openid) through 2.8.0 is vulnerable to SSRF. Ruby-openid performs discovery first, and then verification. This allows an attacker to change the URL used for discovery and trick the server into connecting to the URL, which might be a private server not publicly accessible. Severity can range from medium to critical, depending on how a web application developer chose to employ the ruby-openid library. Developers who based their OpenID integration heavily on the "example app" provided by the project are at highest risk. Affected versions
1.0
1.0.1
1.0.2
1.1.1
1.1.2
1.1.3
1.1.4
2.0.1
2.0.2
2.0.3
2.0.4
2.1.2
+ 15 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
Fixed in
2.9.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2013-1812
GHSA-6c8p-qphv-668v
Oct 24, 2017
Denial of service in ruby-openid
Medium
The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of service (CPU consumption) via (1) a large XRDS document or (2) an XML Entity Expansion (XEE) attack. Affected versions
1.0
1.0.1
1.0.2
1.1.1
1.1.2
1.1.3
1.1.4
2.0.1
2.0.2
2.0.3
2.0.4
2.1.2
+ 7 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
Fixed in
2.2.2
References
Updated Dec 05, 2024 · Source: OSV.dev | ||
1.1.1
minor
2 CVEs
CVE-2019-11027
GHSA-fqfj-cmh6-hj49
Jun 13, 2019
ruby-openid SSRF via claimed_id request
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Ruby OpenID (aka ruby-openid) through 2.8.0 is vulnerable to SSRF. Ruby-openid performs discovery first, and then verification. This allows an attacker to change the URL used for discovery and trick the server into connecting to the URL, which might be a private server not publicly accessible. Severity can range from medium to critical, depending on how a web application developer chose to employ the ruby-openid library. Developers who based their OpenID integration heavily on the "example app" provided by the project are at highest risk. Affected versions
1.0
1.0.1
1.0.2
1.1.1
1.1.2
1.1.3
1.1.4
2.0.1
2.0.2
2.0.3
2.0.4
2.1.2
+ 15 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
Fixed in
2.9.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2013-1812
GHSA-6c8p-qphv-668v
Oct 24, 2017
Denial of service in ruby-openid
Medium
The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of service (CPU consumption) via (1) a large XRDS document or (2) an XML Entity Expansion (XEE) attack. Affected versions
1.0
1.0.1
1.0.2
1.1.1
1.1.2
1.1.3
1.1.4
2.0.1
2.0.2
2.0.3
2.0.4
2.1.2
+ 7 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
Fixed in
2.2.2
References
Updated Dec 05, 2024 · Source: OSV.dev | ||
1.0.2
patch
2 CVEs
CVE-2019-11027
GHSA-fqfj-cmh6-hj49
Jun 13, 2019
ruby-openid SSRF via claimed_id request
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Ruby OpenID (aka ruby-openid) through 2.8.0 is vulnerable to SSRF. Ruby-openid performs discovery first, and then verification. This allows an attacker to change the URL used for discovery and trick the server into connecting to the URL, which might be a private server not publicly accessible. Severity can range from medium to critical, depending on how a web application developer chose to employ the ruby-openid library. Developers who based their OpenID integration heavily on the "example app" provided by the project are at highest risk. Affected versions
1.0
1.0.1
1.0.2
1.1.1
1.1.2
1.1.3
1.1.4
2.0.1
2.0.2
2.0.3
2.0.4
2.1.2
+ 15 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
Fixed in
2.9.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2013-1812
GHSA-6c8p-qphv-668v
Oct 24, 2017
Denial of service in ruby-openid
Medium
The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of service (CPU consumption) via (1) a large XRDS document or (2) an XML Entity Expansion (XEE) attack. Affected versions
1.0
1.0.1
1.0.2
1.1.1
1.1.2
1.1.3
1.1.4
2.0.1
2.0.2
2.0.3
2.0.4
2.1.2
+ 7 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
Fixed in
2.2.2
References
Updated Dec 05, 2024 · Source: OSV.dev | ||
1.0.1
patch
2 CVEs
CVE-2019-11027
GHSA-fqfj-cmh6-hj49
Jun 13, 2019
ruby-openid SSRF via claimed_id request
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Ruby OpenID (aka ruby-openid) through 2.8.0 is vulnerable to SSRF. Ruby-openid performs discovery first, and then verification. This allows an attacker to change the URL used for discovery and trick the server into connecting to the URL, which might be a private server not publicly accessible. Severity can range from medium to critical, depending on how a web application developer chose to employ the ruby-openid library. Developers who based their OpenID integration heavily on the "example app" provided by the project are at highest risk. Affected versions
1.0
1.0.1
1.0.2
1.1.1
1.1.2
1.1.3
1.1.4
2.0.1
2.0.2
2.0.3
2.0.4
2.1.2
+ 15 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
Fixed in
2.9.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2013-1812
GHSA-6c8p-qphv-668v
Oct 24, 2017
Denial of service in ruby-openid
Medium
The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of service (CPU consumption) via (1) a large XRDS document or (2) an XML Entity Expansion (XEE) attack. Affected versions
1.0
1.0.1
1.0.2
1.1.1
1.1.2
1.1.3
1.1.4
2.0.1
2.0.2
2.0.3
2.0.4
2.1.2
+ 7 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
Fixed in
2.2.2
References
Updated Dec 05, 2024 · Source: OSV.dev | ||
1.0
initial
2 CVEs
CVE-2019-11027
GHSA-fqfj-cmh6-hj49
Jun 13, 2019
ruby-openid SSRF via claimed_id request
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Ruby OpenID (aka ruby-openid) through 2.8.0 is vulnerable to SSRF. Ruby-openid performs discovery first, and then verification. This allows an attacker to change the URL used for discovery and trick the server into connecting to the URL, which might be a private server not publicly accessible. Severity can range from medium to critical, depending on how a web application developer chose to employ the ruby-openid library. Developers who based their OpenID integration heavily on the "example app" provided by the project are at highest risk. Affected versions
1.0
1.0.1
1.0.2
1.1.1
1.1.2
1.1.3
1.1.4
2.0.1
2.0.2
2.0.3
2.0.4
2.1.2
+ 15 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
Fixed in
2.9.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2013-1812
GHSA-6c8p-qphv-668v
Oct 24, 2017
Denial of service in ruby-openid
Medium
The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of service (CPU consumption) via (1) a large XRDS document or (2) an XML Entity Expansion (XEE) attack. Affected versions
1.0
1.0.1
1.0.2
1.1.1
1.1.2
1.1.3
1.1.4
2.0.1
2.0.2
2.0.3
2.0.4
2.1.2
+ 7 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
Fixed in
2.2.2
References
Updated Dec 05, 2024 · Source: OSV.dev |